Applications accessible via public networks are subject to a range of network related threats, such as fraudulent activities, contract disputes or disclosure of information to the public. Therefore, detailed risk assessments and proper selection of controls are indispensable. Controls required often include cryptographic methods for authentication and securing data transfer. Application services can make use of secure authentication methods, e.g. using public key cryptography and digital signatures to reduce the risks. Also, trusted third parties can be used, where such services are needed. (NL ISO/IEC, 2015) 10. Protecting Application Services Transactions Information involved in application service transactions should be protected to prevent incomplete transmission, miss-routing, unauthorized message alteration, unauthorized disclosure, unauthorized message duplication or replay. Information security considerations for application service transactions should include the following: a) the use of electronic signatures by each of the parties involved in the transaction; b) all aspects of the transaction, i.e. ensuring that: 1) user’s secret authentication information of all parties are valid and verified; 2) the transaction remains confidential; 3) privacy associated with all parties involved is retained; c) communications path between all involved parties is encrypted; d) protocols used to communicate between all involved parties are secured; e) ensuring that the storage of the transaction details is located outside of any publicl y accessible environment, e.g. on a storage platform existing on the organizational intranet, and not retained and exposed on a storage medium directly accessible from the Internet; f) where a trusted authority is used (e.g. for the purposes of issuing and maintaining digital signatures or digital certificates) security is integrated and embedded throughout the entire end-to-end certificate/signature management process. (NL ISO/IEC, 2015) 11. Planning Information Security Continuity The information security continuity should be embedded in the organization’s business continuity management systems. The organization should determine its requirements for information security and the continuity of information security management in adverse situations, e.g. during a crisis or disaster. An organization should determine whether the continuity of information security is captured within Lebanese National Security Policy Guidelines v1.7 Page “Failing to plan is planning to fail.” – Alan Lakein– American writer 50 |

Select target paragraph3